AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-3281

MEDIUM · CVSS 5.3 EPSS 7.61%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-02-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-3281
Severity
MEDIUM
CVSS
5.3
EPSS
7.61%

Original NVD Description

In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.